CVE-2026-95102
published 2026-10-02CVE-2026-95102: WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this…
PriorityP265critical9.4CVSS 3.1
AVNACLPRNUINSUCHIHAL
EPSS
0.34%
25.4th percentile
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| monta | monta.app | — | — |
CVSS provenance
nvdv3.19.4CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations.
ghsa_unreviewed·2026-10-03
CVE-2026-95102 [CRITICAL] CWE-306 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations.
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
VulDB
Monta monta.app WebSocket endpoints improper authentication
vuldb·2026-10-02·CVSS 9.4
CVE-2026-95102 [CRITICAL] Monta monta.app WebSocket endpoints improper authentication
A vulnerability categorized as critical has been discovered in Monta monta.app. The affected element is an unknown function of the component WebSocket endpoints. The manipulation results in improper authentication.
This vulnerability is reported as CVE-2026-95102. The attack can be launched remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-02
Published